WAZUH All Commands monitor

556 Views Asked by At

How to monitor each and every command executed by user, even in sudo level. I have configured audit rules and they are appearing in audit.logs, but I want to view each command timely from server to Kibana/wazuh manager. enter image description here

1

There are 1 best solutions below

0
On

Auditd share complete commands and users UID too with wazuh if configured properly. So I just added those columns from list in Kibana and now data is apearing fine.